This is a healthy, mature release with a long history since 2017, 270 releases, 40 releases in the last 12 months, and a recent stable release cadence. The repository is active, unarchived, organization-backed by TYPO3-CMS, and shows 11 commits from six active maintainers in the last three months, with only moderate contributor concentration. The package is licensed, has a substantial documented file tree, uses no install-time lifecycle scripts, and has repository tests even though tests are not included in the artifact. The main gaps are the absence of a security policy and security-scanning tooling, while repository workflow data is unavailable because no workflows were analyzed; these reduce transparency somewhat but do not outweigh the strong maintenance and release evidence.
92%
Total Score
90
100
94
90
There were no new or closed issues or pull requests in the last month, which is neutral rather than a strong activity signal because issue and pull-request totals are unavailable.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-process transparency gap.
No repository security policy was found, creating a genuine disclosure and security-process transparency gap despite the package's otherwise strong maintenance evidence.
| Title | Versions | Severity |
|---|---|---|
CVE-2024-55923 typo3/cms-indexed-search is vulnerable to Cross-Site Request Forgery (CSRF) in versions 10.0.0 - 10.4.47, 11.0.0 - 11.5.41, 12.0.0 - 12.4.24 and 13.0.0 - 13.4.2. | 10.0.0 - 10.4.4711.0.0 - 11.5.4112.0.0 - 12.4.24 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version 14.3.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.